Unless you are testing OnConnect to understand it better, for the 2930F switches you are likely better off to implement 802.1X+MAC authentication as described in the same document. I see OnConnect as a fallback scenario only, if you can't configure 802.1X+MAC (or just MACAuth) for some reason. One misconception that I hear sometimes is that OnConnect is better for IoT, which is not true in most cases. MAC Auth is faster and less disruptive for clients as it is pro-active versus re-active for OnConnect.